HUSÁK, Martin, Martin ŽÁDNÍK, Václav BARTOŠ and Pavol SOKOL. Dataset of intrusion detection alerts from a sharing platform. Data in Brief. Elsevier, 2020, vol. 33, December, p. 1-12. ISSN 2352-3409. Available from: https://dx.doi.org/10.1016/j.dib.2020.106530.
Other formats:   BibTeX LaTeX RIS
Basic information
Original name Dataset of intrusion detection alerts from a sharing platform
Authors HUSÁK, Martin (203 Czech Republic, guarantor, belonging to the institution), Martin ŽÁDNÍK (203 Czech Republic), Václav BARTOŠ (203 Czech Republic) and Pavol SOKOL (703 Slovakia).
Edition Data in Brief, Elsevier, 2020, 2352-3409.
Other information
Original language English
Type of outcome Article in a journal
Field of Study 10200 1.2 Computer and information sciences
Country of publisher Netherlands
Confidentiality degree is not subject to a state or trade secret
WWW URL URL
RIV identification code RIV/00216224:14610/20:00116889
Organization unit Institute of Computer Science
Doi http://dx.doi.org/10.1016/j.dib.2020.106530
UT WoS 000600652300195
Keywords in English Cyber security;Intrusion detection alerts;Information exchange;Geolocation;Reputation
Tags rivok
Tags International impact, Reviewed
Changed by Changed by: Mgr. Alena Mokrá, učo 362754. Changed: 27/4/2021 12:04.
Abstract
The dataset contains intrusion detection alerts obtained via an alert sharing platform (SABU) for one week. A plethora of heterogeneous intrusion detection systems deployed across several organizations contributed to the sharing platform. The alerts are stored in the intrusion Detection Extensible Alert (IDEA) format and categorized using the eCSIRT.net Incident Taxonomy. Dataset can be used in several areas of cybersecurity research for the analysis of intrusion detection alerts including temporal and spatial correlations, reputation scoring, attack scenario reconstruction, and attack projection. The network identifiers (e.g., IP addresses, hostnames) are anonymized. However, the list of interesting features (e.g., presence on blacklists, geolocation) of such entities at the time of data collection is provided.
Links
EF16_019/0000822, research and development projectName: Centrum excelence pro kyberkriminalitu, kyberbezpečnost a ochranu kritických informačních infrastruktur
PrintDisplayed: 8/9/2024 10:26